Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 29, 2018 |
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Dec 10, 2025 | Apr 27, 2017 |
| Jenkins 2017 04 26 | — | Upgrade Jenkins to version 2.57Upgrade Jenkins LTS to version 2.46.2Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest version | Jan 29, 2018 | Jan 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub